Data Security When Using SaaS: What Managers Need to Know

A purchasing manager at a textile manufacturer starts using a web-based production planning tool and, a few months in, asks a pointed question: ‘My order data, supplier pricing and inventory figures are no longer on our own servers — can I actually trust that?’ It is a question circulating in the minds of many small and mid-sized business owners who are evaluating hosted software services. The idea of renting software over an internet connection is appealing because it removes installation, maintenance and hardware costs, but the questions of where the data goes, who can access it and what happens when something goes wrong often remain unanswered.

In the hosted software model — referred to internationally as Software as a Service, or SaaS — the vendor hosts both the application and the database on its own infrastructure. The customer company receives only a browser window; every transaction takes place on the vendor’s servers. This arrangement raises a serious trust question, particularly in production and supply chain management where sensitive data is dense. If a manufacturer’s raw material costs, supplier agreements or customer orders were to reach a competitor, the damage could be irreversible.

The first step in any security evaluation is to question the vendor’s physical infrastructure. Where are the servers located, does the data centre have backup systems for fire, flooding or power outages, and what measures are in place against unauthorised physical access? Some vendors serving the Turkish market host their servers abroad, particularly in Western Europe, which introduces additional questions around latency and legal jurisdiction. Requesting data centre documentation and audit reports from the vendor is the right approach at this stage.

The second issue is data encryption. Checking whether data transmitted over the internet is encrypted means looking for SSL certificate usage — an address beginning with ‘https’ in the browser bar and a padlock icon are the basic indicators. Whether data is also encrypted while stored on the server is a separate question. If a vendor cannot give a clear answer or avoids providing technical documentation, that is a warning sign. Encryption alone is not sufficient; the standard being used and how encryption keys are managed should also be asked.

On the matter of access control, it is just as important to question vendor employees’ access to your data as it is to define which of your own staff can reach which records. A reputable vendor restricts its own personnel’s access to customer data through both technical and procedural controls and can document those restrictions. On the customer side, the question of how granularly user permissions can be configured matters: does the purchasing department see only its own module, or are accounting figures also visible? Role-based access control is the core feature to look for at this stage.

Contract terms are often at least as critical as technical details. Does the signed service agreement explicitly state that data ownership belongs to the customer company? If the service is terminated or the vendor becomes insolvent, how will the data be returned and in what format? If there is a service outage, does the vendor carry a compensation obligation and what is the ceiling on that liability? If these questions are not clearly addressed in the contract text, they should be raised during negotiation; vague language can open the door to serious legal and operational problems later on.

A practical difficulty worth acknowledging is that the majority of small and mid-sized businesses in Turkey lack the internal resources to carry out this kind of technical and legal evaluation. In a manufacturing firm without an IT department, there is usually no one available to assess a vendor’s security documentation; the accounting manager or general manager ends up making these judgements within their own knowledge limits and time constraints. In that situation, bringing in an independent consultant or a technical specialist unconnected to the vendor for a short engagement is a reasonable investment when weighed against the value of the contract being signed.

At the decision stage, there are a few core questions every manager should ask: Can the vendor demonstrate its security practices with written documentation? Does the contract clearly address data ownership, return procedures and service outage compensation? Can internal user permissions be configured with enough granularity? If satisfactory answers to these questions are not forthcoming, then however attractive the cost advantages of the hosted software model appear, stopping before signing and evaluating alternative vendors is the sounder course of action.

This article was originally written in Turkish by Gökhan MERCANOĞLU on February 27, 2006 and has been automatically translated into English and other languages using machine translation.


For inventory optimization, the critical question is not which system to use. The real question is which problem will be solved, which data can be trusted, and which action will be accelerated. Without these answers, solutions look modern but only digitize old habits.


Gökhan Mercanoğlu
MRP, Üretim ve Tedarik Zinciri